Apache AirflowGHSA-c732-xvv8-g94c
Command Injection in Apache Airflow and Apache Airflow MySQL Provider
Critical9.8CVE-2023-22884 · Published Jan 21, 2023 · updated Jun 29, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-airflow PyPI | < 2.5.1 | 2.5.1 |
Details and references
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apache Software Foundation Apache Airflow MySQL Provider.This issue affects Apache Airflow: before 2.5.1; Apache Airflow MySQL Provider: before 4.0.0.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-77
- Also known as
- BIT-airflow-2023-22884, CVE-2023-22884, PYSEC-2026-268, PYSEC-2026-279
More Apache Airflow advisories
All Apache Airflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 242023 | Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider. CVE-2023-25693Critical9.8fixed in 3.1.1 | Critical9.8 | 3.1.1 |
| Mar 152023 | Sensitive Information in Error Messages in Apache Airflow CVE-2023-25695Medium5.3fixed in 2.5.2rc1 | Medium5.3 | 2.5.2rc1 |
| Nov 222022 | OS Command Injection in Apache Airflow CVE-2022-40954Medium5.5fixed in 2.3.0 | Medium5.5 | 2.3.0 |
| Nov 222022 | OS Command Injection in Apache Airflow CVE-2022-38649Critical9.8fixed in 2.3.0 | Critical9.8 | 2.3.0 |
| Nov 222022 | OS Command Injection in Apache Airflow CVE-2022-40189Critical9.8fixed in 2.3.0 | Critical9.8 | 2.3.0 |
| Nov 152022 | Apache Airflow Contains Open Redirect CVE-2022-45402Medium6.1fixed in 2.4.3 | Medium6.1 | 2.4.3 |